Integrity and Confidentiality Principle
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.While security and beveiliging topics exist, there is no dedicated topic for the integrity and confidentiality principle specifically as articulated in GDPR Article 5(1)(f), which is a distinct foundational principle requiring separate coverage.
Overview
23 sources · Jul 23, 2026Legal Framework
Article 5(1)(f) GDPR establishes the integrity and confidentiality principle, requiring controllers to process personal data in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage. This principle is operationalized primarily through Article 32 GDPR, which mandates appropriate technical and organizational measures, and Article 28 GDPR, which extends these obligations to processor relationships.
The principle is broader than mere "security" in the technical sense. Recital 75 makes clear that the risk to rights and freedoms encompasses physical, material, and non-material damage — including identity theft, fraud, financial loss, reputational damage, loss of confidentiality of professionally protected data, and unauthorized reversal of pseudonymisation. Recital 85 reinforces that personal data breaches, if not addressed appropriately and timely, can produce precisely these harms. The doctrinal commentary underscores that the scope of required guarantees extends to expertise, reliability, and resources of processors — a wider standard than existed under the 1995 Data Protection Directive, which spoke narrowly of security measures.
Article 28(1) GDPR obligates controllers to engage only processors offering sufficient guarantees regarding appropriate technical and organizational measures. Article 28(3) prescribes in considerable detail what must be contractually binding between controller and processor — a marked expansion from the Directive era.
Key Developments
Enforcement practice confirms that controllers bear full risk when they cannot identify the source of unauthorized access. In the Beekdaelen case, the court held that the municipality's inability to identify who consulted a data subject's personal data, and for what purpose, was a circumstance falling entirely at the controller's risk. Absent a lawful basis for the processing, the court presumed unlawful processing — a demanding standard for organizations with inadequate access logging.
The Dutch DPA (AP) has actively enforced against unlawful processing, including imposing administrative fines and penalty payments on controllers who failed to cease unauthorized livestreaming of personal data. The AP confirmed that administrative fines can be imposed on public authorities for data breaches, signaling that no sector receives preferential treatment.
At the EU level, the CJEU in Weltimmo confirmed that national DPAs may hear claims from data subjects who consider themselves victims of unlawful processing, even where establishment questions remain unresolved. The Dennekamp ruling established that data protection rights and access-to-document rights must both be fully applied without one enjoying primacy over the other — relevant where confidentiality obligations intersect with transparency duties.
The Spanish DPA's enforcement against ENDESA (€60,000 fine) and Free Technologies Excom (€10,000 fine) illustrates that inadequate password management and insufficient verification of processing purposes constitute direct violations of the integrity and confidentiality principle.
Practical Guidance
Implement comprehensive access logging and monitoring: The Beekdaelen ruling makes clear that inability to identify who accessed personal data and why shifts the burden of proof to the controller. Maintain audit trails sufficient to demonstrate lawful processing of every access event.
Conduct processor due diligence on expertise, reliability, and resources: Article 28(1) requires more than contractual representations — assess the processor's actual operational capacity, security certifications, and organizational stability before engaging them.
Execute Article 28(3) processor agreements with full mandatory content: The contractual regime is prescriptive; ensure every required element — subject matter, duration, nature and purpose of processing, type of data, categories of data subjects, and technical/organizational measures — is explicitly addressed.
Map confidentiality obligations against transparency duties: Where sectoral professional secrecy or access-to-information regimes apply, document the balancing analysis to demonstrate full application of both legal frameworks, as required under Dennekamp.
Establish breach response procedures calibrated to Recital 85 harm categories: Assessment of breach severity must account for the full spectrum of potential damages — not just technical compromise but identity theft, financial loss, reputational harm, and reversal of pseudonymisation.